28,679 bytes added
, 11:36, 6 August 2019
{{DISPLAYTITLE:<span style="position: absolute; clip: rect(1px 1px 1px 1px); clip: rect(1px, 1px, 1px, 1px);">{{FULLPAGENAME}}</span>}}
[[fr:Tendances_Technologiques/Chaîne_de_Blocs]]
<div class="mw-collapsible" data-expandtext="Show Detailed View" data-collapsetext="Hide Detailed View">
<div class="sidetable">
<table class="wikitable">
<tr>
<th class="breadcrumb" colspan="2">
<table class="breadcrumb-table">
<tr>
<th>[[Technology_Trends|Technology Trends]]</th>
<th> / </th>
<th>Blockchain</th>
</tr>
</table>
<table class="breadcrumb-table">
<tr>
<th>[[Tendances_Technologiques|Tendances Technologiques]]</th>
<th> / </th>
<th>[[Tendances_Technologiques/Chaîne_de_Blocs|Chaîne de Blocs]]</th>
</tr>
</table>
</th>
</tr>
<tr><td colspan="2" class="logo">[[File:Blockchain_logo.png|200px]]</td></tr>
<tr>
<th>Status</th>
<td>Published</td>
</tr>
<tr>
<th>Initial release</th>
<td>May 23, 2019</td>
</tr>
<tr>
<th>Latest version</th>
<td>May 23, 2019</td>
</tr>
<tr>
<th>Official publication</th>
<td>[[Media:EN_-_Technology_Trends_-_Blockchain.pdf|Blockchain.pdf]]</td>
</tr>
<tr><td colspan="2" class="disclaimer"><table><tr>
<td>[[File:Traffic_cone.png|40px]]</td>
<td class="disclaimerText">This page is a work in progress. We welcome your feedback. Please use the discussion page for suggestions and comments. When the page is approved and finalized, we will send it for translation.</td>
</tr></table></td></tr>
</table>
</div>
<br><p><b>Data Leak Prevention (DLP)</b>, also known as “data loss prevention,” is a cybersecurity solution that includes a variety of strategies, processes, and tools whose purpose is to protect an organization‘s valuable data from being accessed by unauthorized users, released into an untrusted environment, or destroyed.</p>
<div class="mw-collapsible-toggle btn" style="float: left; display: block;">
<div class="toggle mw-collapsible-toggle-collapsed" role="button" tabindex="0"><span class="mw-collapsible-text">Hide Detailed View</span></div>
</div><br><br>
<h2>Business Brief</h2>
<p class="expand mw-collapsible-content">The term data leak or data breach refers to confidential information being released by an insider or an external threat for nefarious purposes. Examples of an organization’s valuable information can include financial data such as a credit card numbers, personal identifiable information (PII) such as the user’s identity, username, password and user activity, intellectual property like patents, trade secrets or source code, or classified documents.</p>
<p class="expand mw-collapsible-content">Without implementing countermeasures, an organization risks the Confidentiality, Integrity, and Availability, known as the CIA or AIC Triad, of their data by leaving themselves vulnerable to cyberattacks. In the past, examples of these incidents have cost organizations millions of dollars in damages and loss of brand reputation.</p>
<p>DLP provides the tools to mitigate data leak incidents from occurring within an organization. DLP software usually includes the following functionalities:</p>
<ul>
<li><b>Protection:</b> DLP tools implement safeguards such as encryptions, access controls and restrictions to mitigate possible vulnerabilities. An organization can regulate file access by classifying data according to their level of security and by defining a set of rules each user has to abide by. </li>
<li><b>Detection:</b> DLP can alert administrators by generating a real-time detailed report on policy violations such as an attacker attempting to access sensitive data. By creating a baseline behavioural profile of standard patterns, the software can detect abnormal or suspicious user activity. Some solutions accomplish this using machine learning. </li>
<li><b>Monitoring:</b> DLP monitors the behaviour of users on how the data is being accessed, used and moved through the IT infrastructure in order to detect irregular or dangerous user activity. If an event is triggered by a rule violation, the system will notify the security personnel. The system gains visibility in order to proactively secure data from leaving the organization on policy violations.</li>
</ul>
<h2>Technology Brief</h2>
<p class="expand mw-collapsible-content">Data Leak Prevention is the practice of detecting and protecting confidential information against data loss, data leakage and data breaches. Cyberattacks are caused by hackers, spies or even insiders, whose objectives include: to damage IT infrastructure, for financial or political gain, status or revenge.</p>
<p class="expand mw-collapsible-content">In this ever-changing landscape, there are several factors that contribute to the increasing threats:</p>
<ul class="expand mw-collapsible-content">
<li><b>Data Value:</b> The monetization of data has created an environment that encourages the persistence of cybercrime.</li>
<li><b>Multitude of Access Points:</b> Many businesses embrace new technologies like social media and mobile devices, but thereby increase their exposure to internal threats by offering data escape paths.</li>
<li><b>Cheap IT Storage Units:</b> Modern storage units are light and cost less, making it easy for an employee to walk out the door with gigabytes of data.</li>
<li><b>Decentralized IT Systems:</b> This type of architecture provides many benefits like openness and information sharing, but makes it difficult for organizations to track and control their information due to lack of governance.</li>
</ul>
<p>DLP technology is usually categorized into three different components related to each state of the data lifecycle: data at rest, data in motion, and data in use. In most DLP products, there is also a central management server acting as the control center of the DLP deployment. This is usually where DLP policies are managed, data is collected from sensors and endpoint agents, and backup and restore is handled. The components of a data leak prevention tool are, in general:</p>
<p><b>Storage DLP:</b> “Data at Rest” refers to data stored on a “device,” for example, on a server, database, workstations, laptops, mobile devices, portable storage or removable media. The term refers to data being inactive and not currently being transmitted across a network or being actively processed. A storage DLP protects this type of data by using several security tools:</p>
<ul>
<li>Data masking hides sensitive information like personal identifiable data.</li>
<li>Access controls prevent unauthorized access.</li>
<li>File encryption adds a layer of protection.</li>
<li>Data classification uses a DLP agent to tag data according to their level of security. Combined with a set of rules, an organization can regulate user access to use, modify and delete information.</li>
<li>A database-activity monitoring tool inspects databases, data warehouses (EDW) and mainframes and sends alerts on policy violations. In order to classify data, some mechanism uses conceptual definitions, keywords or regular expression matching.</li>
</ul>
<p>Network DLP: “Data in Motion” is data that is actively traveling across a network such as email or a file transferred over File Transfer Protocol (FTP) or Secure Socket Shell (SSH). A Network DLP focuses on analyzing network traffic to detect sensitive data transfer in violation of security policies and providing tools to ensure the safety of data transfer. Examples of this include:</p>
<ul>
<li>An email monitoring tool can identify if an email contains sensitive information and block the action or encrypt the content.</li>
<li>The Intrusion Detection System (IDS) monitors for any malicious activity occurring on the network and typically reports to an administrator or to the central management server using a Security Information and Event Management system (SIEM).</li>
<li>Firewall and antivirus software are commonly available products included in a DLP strategy.</li>
</ul>
<p>Endpoint DLP: “Data in Use” is the data currently being processed by an application. Data of this nature is in the process of being generated, updated, viewed, and erased on a local machine. Protecting this type of data is a challenging task because of the large number of systems and devices but it is usually done through an Endpoint DLP agent installed on the local machine. Some characteristics are:</p>
<ul>
<li>The tool provides strong user authentication, identity management and profile permissions to secure a system.</li>
<li>It can monitor and flag unauthorized activities that users may intentionally or unintentionally perform, such as print/fax, copy/paste and screen capture.</li>
<li>Some DLP agents may offer application control to determine which application can access protected data.</li>
<li>There are advanced solutions that use machine learning and temporal reasoning algorithms to detect abnormal behavior on a local machine.</li>
</ul>
<h2>Industry Usage</h2>
<p>The most well-known use of blockchain is in support of cryptocurrencies, such as Bitcoin. A digital currency launched in 2009, Bitcoin does not rely on a monetary authority to monitor verify or approve transactions, but rather relies on a peer-to-peer computer network made up of its users’ machines to do that. Blockchain can be used for all sorts of inter-organizational cooperation. In 2017, Harvard Business Review estimated that approximately 15% of banks are expected to be using blockchain.<ref>Gupta, V. (28 February 2017). <i>[https://hbr.org/2017/02/a-brief-history-of-blockchain A Brief History of Blockchain].</i> Retrieved on 23 May 2019</ref></p>
<p>Although Bitcoin is the first and most well-known use of the blockchain technology, it is only one of about seven hundred applications that use the blockchain distributed ledger system. Blockchain is a digital ledger on top of which organizations can build trusted applications, via a secure chain of custody for digital records.</p>
<h2>Canadian Government Use</h2>
<p class="expand mw-collapsible-content">Canada does not currently have a federal policy on blockchain. While blockchain is an important emerging technology, how it could be used by the Government remains to be seen. At this point, the ideal GC use case for blockchain would be a system of public record to register secure transactions from multiple contributors toward distributing a single source of truth in a non-refutable fashion.</p>
<p>According to Gartner, there is no Government around the world that is operating a true blockchain initiative , although some (State of Georgia, Hong Kong, United Arab Emirate) are operating pseudo-initiatives and starting to experiment with the technology.<ref>Gartner conference call.</ref> Treasury Board of Canada notes highlights a few specific initiatives: Estonia uses an eHealth Foundation partnership to accelerate blockchain-based systems to ensure security, transparency, and auditability of patient healthcare records. Singapore employs the use of blockchain to prevent traders from defrauding banks through a unique distributed ledger-based system focused on preventing invoice fraud.<ref>Treasury Board of Canada</ref></p>
<p>In 2017, “The Blockchain Corridor: Building an Innovation Economy in the 2nd Era of the Internet” was developed, discussing ways to turn Canada into a global hub for the “Blockchain revolution.” Written by a high-tech think tank and prepared for / partially funded by the federal Department of Innovation, Science and Economic Development (ISED), the report lays out a few proposals regarding how to cement Canada’s role as a world leader in blockchain technology. The Canadian Government announced in July 2017 the intention to run at least 6 select pilot projects on the use of blockchain.<ref>Secretariat, T. B. (29 March 2019). <i>[https://www.canada.ca/en/government/system/digital-government/digital-operations-strategic-plan-2018-2022.html Digital Operations Strategic Plan: 2018-2022].</i> Retrieved on 23 May 2019</ref></p>
<p class="expand mw-collapsible-content">This included establishing a digital economy commission, which will be tasked with developing solid recommendations regarding how Canada can become a leader in developing technologies such as blockchain, quantum computing, artificial intelligence and self-driving vehicles. It also recommended getting governments currently using blockchain to transform their own operations and provide examples of how the technology can benefit public sectors in Canada and abroad. Governments could use blockchain to verify the payment of taxes and manage public services more efficiently.</p>
<h2>Implications for Government Agencies</h2>
<h3>Shared Services Canada (SSC)</h3>
<h4>Value Proposition</h4>
<p class="expand mw-collapsible-content">Collaborative technologies like blockchain promise the ability to improve the business processes that occur between organizations and entities, radically lowering the “cost of trust.” As a result, blockchain may offer significantly higher returns for each investment dollar spent than that of traditional internal investments, but in doing so means collaborating with customers, citizens, suppliers and competitors in new ways.<ref>Treasury Board of Canada, Blockchain: Ideal Use Cases for the Government of Canada, 5.</ref></p>
<p>Blockchain offers a numbers of benefits to the Government of Canada, such as a reduction in costs and complexity, trusted record keeping and user-centric privacy control. It offers significant opportunities in terms of a single source for public records, support for multiple contributors and a technology ideal for multi-jurisdictional interactions. Due to its decentralized, collaborative nature, it potentially aligns well with policies and practices around Open Government, which aim to make Government services, data, and digital records more accessible to Canadians.</p>
<p>By eliminating the duplication and reducing the need for intermediaries, blockchain technology could be used by SSC to speed-up aspects of service delivery. A challenge for SSC in terms of blockchain will be to identify which enterprise solutions emerge as leaders and how they deal with privacy, confidentiality, auditability, performance and scalability.</p>
<p class="expand mw-collapsible-content">Currently, a number of Government agencies are engaged in Blockchain in a number of ways. Maybe SSC could support the following departments in their initiatives to explore how Blockchain can help solve these issues:
<ul>
<li><b>Elections Canada</b> – practical applications to support Voter List Management, Secure Identity Management, and management of electoral geography.</li>
<li><b>Financial Transactions and Reports Analysis Centre of Canada</b> – exploring implications for anti-money laundering and counter-terrorism financing.</li>
<li><b>Public Safety Canada</b> – focused on various uses and misuses of virtual currencies, such as extortion or blackmail.</li>
<li><b>Natural Resources Canada</b> – use as a public registry for the disclosure of payments under the Extractive Sectors Transparency Measures Act.</li>
<li><b>Bank of Canada</b> – exploring a proof of concept model alongside Payments Canada, Canadian commercial banks and the R3 consortium.</li>
<li><b>ISED</b> – engagement with Government departments, provincial-territorial-municipal partners, and key industry players.</li>
</ul>
</p>
<h4>Challenges</h4>
<p class="expand mw-collapsible-content">There are weaknesses in terms of technological complexity, intensive computational and storage demands and a requirement for common software across all nodes. There are significant challenges particularly important within a governmental process. Truly digital assets with a single copy can be destroyed and a government network housing such assets would represent a very public target for malicious actors.<ref>Vallée, J.-C. L. (April 2018). <i>[Vallée, J.-C. L. (April 2018). <i>[https://www.conferenceboard.ca/temp/7dc77c07-7e5a-4be6-ad6d-7d1070f9ac20/9591_Cautious%20Optimism_BR.pdf Adopting Blockchain to Improve Canadian Government Digital Services].</i> Retrieved on 23 May 2019 Adopting Blockchain to Improve Canadian Government Digital Services].</i> Retrieved on 23 May 2019</ref></p>
<p class="expand mw-collapsible-content">It is important to remember that Blockchain, while a technological innovation in transactional business and chain of digital custody, is not a single solution to transactional challenges facing the GC.</p>
<p class="inline">The amount of time and energy required to maintain the blockchain and create new blocks is not small and this is a frequent criticism of the technology. Conventional database entry, such as using SQL, takes only milliseconds, compared to blockchain, which takes several minutes. Due to the length of time required as well as the need for multiple computers to verify the blocks, blockchains consume an enormous amount of energy.</p><p class="expand inline mw-collapsible-content"> However, as technology advances, the blockchain consensus process takes closer to three minutes with Ethereum, which is currently among the most advanced blockchains available.xxiii Even older blockchains, such as Bitcoin, are still faster than traditional financial transactions, such as the stock exchange, which can take days to be verified and finalized. Despite this, services or transactions that require rapid speed, may not be suitable for blockchain.</p>
<p class="inline-spacer"></p>
<p class="inline">There are also some concerns with respect to privacy. Since blockchain is built on the premise of decentralization and transparency, the data within the chain is technically available for anyone on the network, provided they have the computational power and knowledge to gain access. Instead of being identified on the network by name, users have encryption keys, which is a list of seemingly random numbers and letters.</p><p class="expand inline mw-collapsible-content"> While more private than a name or other demographic information, users could still be identified by their keys over time. Also, any data contained within a block that may have personal information that an individual wishes to keep private, such as medical records for example, may not be well suited for a blockchain as it will be transparent and visible to other users.<ref>Diedrich, H. (2016). <i>Ethereum: Blockchains, Digital Assets, Smart Contracts, Decentralized Autonomous Organizations.</i> Scotts Valley: CreateSpace Independent Publishing Platform.</ref></p>
<h4>Considerations</h4>
<p class="expand mw-collapsible-content">By using an agreed upon consensus algorithm, collaborative technology like Blockchain promises the ability to improve the business processes that occur between organizations and entities, radically lowering the “cost of trust.” The cost of trust is lowered because there is only one record of a transaction that needs to be kept and all stakeholders trust that record.</p>
<p>In a traditional transaction, all stakeholders have to keep a record of the transaction and in the case of a discrepancy, it was more difficult / costly to determine the accuracy of a record. As a result, Blockchain may offer significantly higher returns for each investment dollar spent than that of traditional internal investments. However, to doing so, it means collaborating with customers, citizens, suppliers and competitors in new ways.<ref>Treasury Board of Canada, Blockchain: Ideal Use Cases for the Government of Canada, 5. </ref></p>
<p class="inline">Further research is needed to understand the potential impacts that blockchain could have on SSC as a service provider as well on the usage amounts the GC would require. SSC should consider the identification of client areas where blockchain may be leveraged. It may be required that client departments self-identify spaces which could benefit from blockchain processes.</p><p class="expand inline mw-collapsible-content"> A challenge for SSC will be to identify which partner organizations and enterprise solutions require priority blockchain pilot projects as well as be able to identify departments that emerge as leaders and how they deal with privacy, confidentiality, auditability, performance and scalability.</p>
<p>Lastly, SSC and the GC should consider the capacity issues in resources, network capabilities, and time required to create and maintain blockchain networks on its own. Blockchain is not a pedestrian technology, it will require dedicated teams that are appropriately resourced and financed in order for the technology to be deployed as any other service. SSC may wish to consider looking for private sector companies that specialize in providing Blockchain as a Service (BaaS), and determine the risk and cost benefits of outsourcing this process altogether.</p>
<h2>Hype Cycle</h2>
<div class="container">
<div class="row">
<div class="col-sm-8">[[File:EN_Technology_Trends_-_Blockchain_Hype_Cycle_2018.png|center]]</div>
<div class="col-sm-4">
<table class="wikitable hypecycleTable">
<tr>
<th>English</th>
<th>Français</th>
</tr>
<tr>
<td>Figure 1. Hype Cycle for Blockchain Technologies, 2018</td>
<td>Figure 1. Rapport Hype Cycle sur les technologies de la chaîne de blocs, 2018</td>
</tr>
<tr>
<td>Expectations</td>
<td>Attentes</td>
</tr>
<tr>
<td>Time</td>
<td>Temps</td>
</tr>
<tr>
<td>Blockchain Wallet Platform</td>
<td>Plate-forme de portefeuille de la chaîne de blocs</td>
</tr>
<tr>
<td>Blockchain Interoperability</td>
<td>Interopérabilité de la chaîne de blocs</td>
</tr>
<tr>
<td>Postquantum Blockchain</td>
<td>Chaîne de blocs post-quantique</td>
</tr>
<tr>
<td>Smart Contract Oracle</td>
<td>Oracle des contrats intelligents</td>
</tr>
<tr>
<td>Zero Knowledge Proofs</td>
<td>Preuve à divulgation nulle de connaissance</td>
</tr>
<tr>
<td>Distributed Storage in Blockchain</td>
<td>Stockage distribué dans la chaîne de blocs</td>
</tr>
<tr>
<td>Smart Contracts</td>
<td>Contrats intelligents</td>
</tr>
<tr>
<td>Blockchain for IAM</td>
<td>Chaîne de blocs pour la gestion des identités et de l’accès</td>
</tr>
<tr>
<td>Blockchain PaaS</td>
<td>Chaîne de blocs à titre de PaaS</td>
</tr>
<tr>
<td>Blockchain for Data Security</td>
<td>Chaîne de blocs pour la sécurité des données</td>
</tr>
<tr>
<td>Decentralized Applications</td>
<td>Applications décentralisées</td>
</tr>
<tr>
<td>Consensus Mechanisms</td>
<td>Mécanismes de consensus</td>
</tr>
<tr>
<td>Metacoin Platforms</td>
<td>Plates-formes de Metacoin</td>
</tr>
<tr>
<td>Sidechains/Channels</td>
<td>Chaînes latérales/canaux</td>
</tr>
<tr>
<td>Multiparty Computing</td>
<td>Calcul multipartite</td>
</tr>
<tr>
<td>Cryptocurrency Hardware Wallets</td>
<td>Portefeuilles matériels de cryptomonnaie</td>
</tr>
<tr>
<td>Cryptocurrency Software Wallets</td>
<td>Portefeuilles logiciels de cryptomonnaie</td>
</tr>
<tr>
<td>Blockchain</td>
<td>Chaîne de blocs</td>
</tr>
<tr>
<td>Distributed Ledgers</td>
<td>Grands livres distribués</td>
</tr>
<tr>
<td>Cryptocurrency Mining</td>
<td>Minage de cryptomonnaie</td>
</tr>
<tr>
<td>Innovation Trigger</td>
<td>Déclencheur d’innovation</td>
</tr>
<tr>
<td>Peak of Inflated Exepctations</td>
<td>Pic des attentes exagérées</td>
</tr>
<tr>
<td>Trough of Disillusionment</td>
<td>Gouffre des désillusions</td>
</tr>
<tr>
<td>Slope of Enlightenment</td>
<td>Pente de l’illumination</td>
</tr>
<tr>
<td>Plateau of Productivity</td>
<td>Plateau de productivité</td>
</tr>
<tr>
<td>As of July 2018</td>
<td>En date de juillet 2018</td>
</tr>
<tr>
<td>Plateau will be reached:</td>
<td>Le plateau sera atteint :</td>
</tr>
<tr>
<td>Less than 2 years</td>
<td>dans moins de 2 ans</td>
</tr>
<tr>
<td>2 to 5 years</td>
<td>dans 2 à 5 ans</td>
</tr>
<tr>
<td>5 to 10 years</td>
<td>dans 5 à 10 ans</td>
</tr>
<tr>
<td>More than 10 years</td>
<td>dans plus de 10 ans</td>
</tr>
<tr>
<td>Obsolete before plateau</td>
<td>Désuet avant le plateau</td>
</tr>
<tr>
<td>Source: Gartner (July 2018)</td>
<td>Source : Gartner (juillet 2018)</td>
</tr>
</table>
</div>
</div>
</div>
<h2>References</h2>
</div>
{{#css:
div>a>img {
width: 100%;
height: auto;
}
#firstHeading::after{
content:"Data Leak Prevention";
}
/* PC Formatting */
.sidetable{ float: right; width: 25%; cursor: auto; text-align: center;}
.wikitable{ margin: 0px 0px 0px 0px; }
.logo{ text-align: center; }
.disclaimer{ border: 1px solid red; background-color: rgba(255, 0, 0, 0.3); }
.breadcrumb{
background-color: rgb(248, 249, 250);
border: 1px solid rgb(162, 169, 177);
}
.breadcrumb-table{ margin: auto; }
.expand{ background-color: rgba(242, 109, 33, 0.2); }
.mw-collapsible-text{ text-align:left; }
.inline{ display: inline; }
.inline-spacer{ display: block; }
.btn {
display: inline-block;
margin-bottom: 0;
font-weight: 400;
text-align: center;
white-space: nowrap;
vertical-align: middle;
-ms-touch-action: manipulation;
touch-action: manipulation;
cursor: pointer;
background-image: none;
border: 1px solid transparent;
padding: 6px 12px;
font-size: 14px;
line-height: 1.42857143;
border-radius: 4px;
-webkit-user-select: none;
-moz-user-select: none;
-ms-user-select: none;
user-select: none;
width: 230px;
color: rgba(242, 109, 33, 1);
background-color: rgba(242, 109, 33, 0.1);
border-color: rgba(242, 109, 33, 1);
text-decoration: none;
}
.btn:hover {
color: rgba(255, 255, 255, 1);
background-color: rgba(242, 109, 33, 1);
text-decoration: none;
}
.hypecycle {
width: 80%;
margin: auto;
}
.container{
width: 100%;
display: block;
}
.row{
width: 100%;
display: table;
content: " ";
}
.col-sm-8{
width: 66.6666666666%;
float:left;
}
.col-sm-4{
width: 33.33333333333%;
float:left;
}
.hypecycleTable{
width: 100%;
}
/* Mobile Formatting */
@media (max-width: 992px){
.sidetable{ width: 80%; margin-left: 10%; margin-right: 10%;}
.container{
display: block;
clear: both;
}
.col-sm-8,
.col-sm-6,
.col-sm-4{
display: block;
width: 100%;
clear: both;
margin: auto;
}
}
@media (max-width: 600px){
.sidetable{ width: 100%; margin-left: 0px; margin-right: 0px;}
}
}}